2026-07-20
2026-07-20 16:16Z
CRIT

CVE-2026-35198 — HeyForm: Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35198

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes when a team owner views the form, leading to complete account takeover through privilege escalation. Version 3.0.0-rc.7 contains a patch for the issue. CVSSv3.1 9.0 (CRITICAL)

CWECWE 79VNDHeyformTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-20
2026-07-20 16:16Z
HIGH

CVE-2026-28220 — Wazuh: Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28220

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or any actor able to authenticate to the cluster channel using the shared cluster key, to make the master node deserialize an attacker-controlled callable and execute it under an attacker-controlled RBAC context. The cluster code in `framework/wazuh/core/cluster/common.py` deserialize CVSSv3.1 8.4 (HIGH)

CWECWE 502VNDWazuhTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-20
2026-07-20 16:16Z
HIGH

CVE-2026-25039 — Parsec: The application does not sanitize the workspace name, creating a vulnerability if that workspace

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25039

Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanitize the workspace name, creating a vulnerability if that workspace name is a UNC path. When creating mountpoint in the windows filesystem to mount the workspace of an organization, the application does not sanitize the workspace name. The cause issue if the workspace name evaluate to a UNC path since it's allowed for the name to containt `\` char. If the UNC CVSSv3.1 8.8 (HIGH)

CWECWE 40VNDParsecTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-20
2026-07-20 16:16Z
HIGH

CVE-2026-21824 — HCL: Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-21824

HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations. CVSSv3.1 8.8 (HIGH)

CWECWE 266VNDHclTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-20
2026-07-20 15:16Z
HIGH

CVE-2026-63090 — ProFTPD: before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63090

ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding the 16 KB reassembly buffer in the fxp.c component. Attackers can supply oversized fragments to trigger an incorrectly conditioned reallocation, corrupt pool freelist metadata, overwrite the root_fs BSS global pointer to reference a CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDProftpdTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-20
2026-07-20 15:16Z
CRIT

CVE-2026-63071 — Isolation: Improper Isolation or Compartmentalization vulnerability in Apache Syncope.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63071

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing the Groovy security sandbox. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by tightening the Groovy security CVSSv3.1 9.8 (CRITICAL)

CWECWE 653VNDIsolationTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-20
2026-07-20 15:16Z
HIGH

CVE-2026-62418 — Low: Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62418

Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue. CVSSv3.1 8.1 (HIGH)

CWECWE 918VNDLowTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-20
2026-07-20 15:16Z
CRIT

CVE-2026-62183 — Privilege: A REST API call can allow the user to grant themselves one or more

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62183

Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is configured, bearing a BPMN definition not requiring admin approval for user self registration of self update requests the following scenario could happen. A REST API call can allow the user to grant themselves one or more of defined Roles, thus gaining their Entitlements and becoming in fact an administrator; th CVSSv3.1 9.8 (CRITICAL)

CWECWE 269TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-20
2026-07-20 15:16Z
CRIT

CVE-2026-57308 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57308

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameters. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-20
2026-07-20 15:16Z
CRIT

CVE-2026-53421 — Isolation: An administrator with adequate entitlements can achieve remote code execution through the connector subsystem

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53421

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue CVSSv3.1 9.8 (CRITICAL)

CWECWE 653VNDIsolationTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-20
2026-07-20 15:16Z
CRIT

CVE-2026-53405 — Isolation: Improper Isolation or Compartmentalization vulnerability in Apache Syncope.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53405

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. When a BPMN process containing a Groovy scriptTask is imported and started, the Groovy script is executed directly on the server, with no sandbox. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1 CVSSv3.1 9.8 (CRITICAL)

CWECWE 653VNDIsolationTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-20
2026-07-20 15:16Z
HIGH

CVE-2026-45270 — CI4MS: The public renderer for pages (`Home::index()` → `app/Views/templates/default/pages.php`) emits `$pageInfo->content` without `esc()`, yielding stored

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45270

CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-keyed page content but persists the raw, un-purified POST value into the database. The public renderer for pages (`Home::index()` → `app/Views/templates/default/pages.php`) emits `$pageInfo->content` without `esc()`, yielding stored XSS that fires for every public visitor of the affected page — includi CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDCi4msTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-20
2026-07-20 15:16Z
CRIT

CVE-2026-12701 — A path traversal vulnerability was found in pulpcore.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12701

A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such as "../" anywhere in the path. An authenticated administrator can craft a relative_path containing embedded traversal sequences (e.g., "looking/normal/../../../../etc/shadow") that escapes the intended export directory during FilesystemExport operations. Because the file content CVSSv3.1 9.0 (CRITICAL)

CWECWE 22TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-20
2026-07-20 15:15Z
CRIT

Dnsmasq DNS Remote Heap Buffer Overflow

Exodus Intel·blog.exodusintel.comCVE-2026-2291

Exodus Intelligence disclosed a remote heap buffer overflow in Dnsmasq (CVE-2026-2291) introduced in v2.73 and patched in v2.92rel2/v2.93. The vulnerability stems from unsafe strcpy() in the cache system when processing escaped domain names from upstream DNS replies; names exceeding 1,025 bytes overflow the bigname buffer. The researchers demonstrated full RCE on OpenWRT by chaining heap overflow with write-what-where primitives to overwrite function pointers in ld.so.

TACTA0002SRFNetworkSWDnsmasqTYPResearchTYPVulnerabilitySTGExecutionSTGInitial AccessTECT1190
92
Edit Score
2026-07-20
2026-07-20 13:16Z
HIGH

CVE-2026-16248 — Tenda: The manipulation of the argument GetValue/SetValue results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16248

A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. The manipulation of the argument GetValue/SetValue results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-20
2026-07-20 13:00Z
CRIT

From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab

Rapid7 Research·rapid7.comCVE-2025-33053CVE-2026-21513CVE-2025-24054in the wild

Rapid7 researchers discovered an exposed WebDAV malware delivery infrastructure containing 1,048 artifacts organized as a fully operational QA testing lab. The attacker systematically tested delivery chains including CVE-2025-33053 (Windows Internet Shortcut RCE), filename spoofing techniques, and multiple execution vectors (WebDAV, UNC paths, search-ms, library-ms). Analysis revealed two active campaigns: a CURP phishing operation targeting Mexico with a fileless .NET stealer (2,384 recorded interactions), and a DlrtyGames DLL-sideloading chain deploying a modular RAT with keylogging and wallet-targeting capabilities.

TACTA0005TACTA0001TACTA0002SRFNetworkTACTA0006TACTA0007SRFWebTACTA0009
92
Edit Score
2026-07-20
2026-07-20 12:19Z
HIGH

CVE-2026-64623 — Network: Unauthenticated attackers can submit forged APS delegation payloads with arbitrary scopes to bypass signature

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64623

Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accepts any non-empty string as valid. Unauthenticated attackers can submit forged APS delegation payloads with arbitrary scopes to bypass signature verification and obtain signed permission-grant tokens for sensitive resources including SHELL_EXEC. CVSSv3.1 8.6 (HIGH)

CWECWE 347VNDNetworkTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-20
2026-07-20 12:19Z
CRIT

CVE-2026-64620 — FreeRDP: before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64620

FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer via BN_bn2bin() and only afterward checks output_length > out_length, so out-of-bounds bytes are written before the bounds check. On the server side, when a client selects RDP Standard Security, the encrypted client random is decrypted into a fixed 32-byte buff CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDFreerdpTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-20
2026-07-20 12:19Z
HIGH

CVE-2026-63763 — Surrealdb Surrealdb: before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63763

SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileged users (e.g., those with the database editor role) can create or modify fields containing futures, functions, or closures. Because these are executed in the context of the invoking/querying user rather than their creator, an attacker can plant malicious logic that executes with a higher-privileged user's permissions when that user reads or writes the affec CVSSv3.1 8.8 (HIGH) · EPSS 15th percentile

CWECWE 639VNDSurrealdbTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-20
2026-07-20 12:19Z
HIGH

CVE-2026-63757 — SurrealDB: versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63757

SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns attached session UUIDs without authentication and accepts arbitrary session fields with no ownership verification. Unauthenticated attackers can enumerate session UUIDs and impersonate authenticated sessions to read, write, delete data and escalate privileges. CVSSv3.1 8.8 (HIGH)

CWECWE 306VNDSurrealdbTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-20
2026-07-20 12:19Z
HIGH

CVE-2026-63756 — SurrealDB: versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63756

SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to inherit authenticated session state. Unauthenticated attackers can send concurrent requests to the /rpc endpoint while legitimate authenticated traffic is active to execute operations with hijacked user privileges. CVSSv3.1 8.1 (HIGH)

CWECWE 362VNDSurrealdbTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-20
2026-07-20 12:19Z
HIGH

CVE-2026-63735 — SurrealDB: versions before 3.2.0 fail to validate namespace and database scope in custom API

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63735

SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticated users to invoke endpoints in different namespaces/databases. Attackers with valid credentials for any namespace/database can access custom API endpoints in other tenants by specifying the target scope in the URL path, reading sensitive data or triggering unintended operations. CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDSurrealdbTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-20
2026-07-20 08:16Z
CRIT

CVE-2026-16242 — A flaw was found in the Konnectivity proxy-server configuration for hosted control planes.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16242

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic. CVSSv3.1 9.4 (CRITICAL)

CWECWE 306TYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-07-20
2026-07-20 08:16Z
HIGH

CVE-2026-13577 — Dancer2: Predictable session ids could allow an attacker to gain access to systems.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13577

Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id when both Math::Random::ISAAC::XS and Crypt::URandom are unavailable. The fallback session id is generated from a SHA-1 hash of a call to the built-in rand function, the absolute path of the Dancer2::Core::Role::SessionFactory module, an internal counter, the proc CVSSv3.1 8.2 (HIGH)

CWECWE 338CWECWE 340VNDDancer2TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-20
2026-07-20 07:16Z
CRIT

CVE-2026-16235 — Crypt: Crypt::Password versions through 0.28 for Perl generate insecure random values for salts.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16235

Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography. CVSSv3.1 9.8 (CRITICAL)

CWECWE 338VNDCryptTYPVulnerability
9.8
CVSS v3.1
99
Edit Score